Data Protection Officer
Data Protection Officer (DPO) London Hybrid Working We're working with a leading international law firm looking to appoint an experienced Data Protection Officer (DPO) to join its established Risk & Compliance team.This is an excellent opportunity for an experienced privacy professional to take ownership of the firm's global data protection programme, working alongside senior stakeholders, legal specialists, information security and data governance teams to ensure compliance with UK GDPR, EU GDPR and wider international privacy legislation.If you're looking for a role where you can genuinely influence privacy strategy, governance and regulatory compliance within a highly respected professional services environment, this could be the perfect next step The Role? As the firm's Data Protection Officer, you'll act as the subject matter expert for all things data privacy, providing strategic advice across the business while ensuring the organisation maintains a robust and effective privacy framework.
- Leading and developing the firm's data protection and privacy governance framework.
- Advising the business on compliance with UK GDPR, EU GDPR and wider global privacy legislation.
- Conducting and overseeing Data Protection Impact Assessments (DPIAs) and Data Transfer Impact Assessments (DTIAs).
- Maintaining Records of Processing Activities (RoPA) and supporting data mapping initiatives.
- Reviewing supplier and third-party processing arrangements, including Article 28 agreements, SCCs and IDTAs.
- Managing privacy compliance across business projects, new technologies and operational change.
- Advising on AI governance, automated decision-making and emerging technology from a privacy perspective.
- Leading responses to Data Subject Access Requests (DSARs) and other individual rights requests.
- Managing personal data breach response and regulatory notification requirements.
- Delivering engaging privacy training across the business.
- Carrying out internal privacy audits and monitoring ongoing compliance.
- Monitoring legislative developments and implementing regulatory change where required.
- Working closely with Risk & Compliance, Information Security, Procurement and Data Governance teams to manage data-related risk across the business.
- Experience working as a Data Protection Officer, Privacy Manager, Data Privacy Manager or similar.
- Strong working knowledge of UK GDPR, EU GDPR and wider international privacy legislation.
- Experience within a regulated environment, ideally legal or professional services.
- A legal qualification (or equivalent data privacy experience).
- Experience managing DPIAs, DTIAs, RoPA, DSARs, privacy audits and breach management.
- Strong stakeholder management skills with the ability to influence at all levels.
- Experience developing privacy policies, governance frameworks and training programmes.
- An industry-recognised privacy qualification such as CIPP/E, CIPM, CIPT, ISEB or similar (or a willingness to obtain one).